Last updated: 17.07.2026

Cybersecurity law in Poland and EU: Legal and Regulatory Guide for Businesses
With the development of EU and national regulations, cybersecurity has become one of the key areas of compliance for entrepreneurs operating in Poland. Today, legal requirements cover not only the financial sector or critical infrastructure operators, but also technology companies, manufacturing enterprises, digital service providers, e-commerce entities, and other regulated entities operating in the digital economy.
Cybersecurity has ceased to be solely a technological issue within the competence of IT departments. Increasingly, it is an element of risk management and corporate governance, influencing the organization of internal processes, relationships with technology suppliers, and the liability of company executives. This is of particular importance for entities operating in the digital environment, for whom business continuity of IT systems, data security, network security, and operational resilience are fundamental conditions for conducting business.
Proper implementation of the requirements resulting from cybersecurity regulations allows companies to mitigate legal and operational risks and prepare the enterprise for the demands of supervisory authorities, business partners, and participants in international supply chains. It also helps strengthen organizational resilience and ensure that companies are better prepared to respond to cyber attacks, regulatory scrutiny, and disruptions affecting business continuity.
The following article provides a comprehensive introduction to the most important regulatory obligations and legal risks associated with cybersecurity in Poland, developed from the perspective of entrepreneurs and investors operating on the Polish market.
NIS2 Directive in Poland: UKSC, Essential Entities and the CER Directive
The implementation of the NIS2 Directive as part of European Union law, into the Polish legal order has significantly expanded the catalog of entrepreneurs subject to cybersecurity obligations. The regulations no longer apply solely to critical infrastructure operators, but also to many enterprises operating in the digital, manufacturing, logistics, healthcare, and service sectors, as well as entities relevant to public administration, telecommunications services, national defence, and crisis management.
The new regulations are based on the principle of self-identification, which means that entrepreneurs are independently responsible for assessing whether they hold the status of an essential or important entity, and whether they are subject to the obligation to register in the S46 system.

In Poland, these obligations are set out in the Act on the National Cybersecurity System (UKSC), often referred to in English as the National Cybersecurity System Act. According to the current implementation schedule, businesses subject to the regulation will be required to complete the identification process and register by October 3, 2026 at the latest.
In practice, compliance with NIS2 requires implementing appropriate risk management measures, preparing incident reporting procedures, securing the supply chain, and ensuring proper oversight at the board level. This includes risk assessment, vulnerability assessments, and the use of threat intelligence where necessary to identify and respond to cybersecurity incidents in a timely manner. Mandatory audits and the personal liability of managers for the implementation of statutory requirements are also becoming significant elements of the new regulations. The deadline for the full implementation of the information security management system and all required organizational and technical measures is set for April 3, 2027.
From the perspective of organizational resilience and physical infrastructure, these regulations remain closely linked to the CER Directive on the resilience of critical entities. Entrepreneurs within the scope of CER must prepare not only for cyber threats, but also for operational disruptions, physical incidents, and events affecting the continuity of essential services. Crucially, any critical entity classified under CER is automatically recognized as an essential entity within the meaning of NIS2, which means the necessity of parallel compliance with the requirements resulting from both regulatory regimes.
We support entrepreneurs in assessing their regulatory status, navigating the self-identification process, registering in the S46 system, implementing compliance procedures, and preparing the organization for audits and inspections conducted by competent supervisory authorities.
Cyber Resilience Act (CRA): Cybersecurity Obligations for Technology Providers
The Cyber Resilience Act (CRA) regulation introduces uniform cybersecurity requirements for products with digital elements across the entire European Union.
In practice, the CRA significantly changes the approach to liability for the security of digital products, shifting the burden of risk and vulnerability management directly onto the entities placing products on the EU market. The regulation covers not only manufacturers of devices and IoT solutions, but also providers of software, applications, and industrial systems, as well as entrepreneurs importing or selling digital products under their own brand.
In practice, this means that cybersecurity requirements must be taken into account as early as the product’s design and development stage, in accordance with the Security by Design principle. An entrepreneur’s obligations do not end with the sale of the product but span its entire lifecycle, including vulnerability management, providing security updates, and maintaining appropriate technical documentation.
From September 11, 2026, manufacturers will also be obliged to actively report actively exploited vulnerabilities and security incidents.
Furthermore, the regulation introduces an obligation to provide a Software Bill of Materials (SBOM) and to ensure free security updates, as a rule, for a period of at least five years or for the expected lifetime of the product.
In many cases, compliance with CRA requirements will be a prerequisite for obtaining the CE marking and continuing to place products on the European Union market.

We advise manufacturers, importers, and distributors on product risk classification, identifying obligations arising from the CRA, preparing the required documentation, and guiding the organization through the conformity assessment and certification process for digital products.
GDPR and Cybersecurity Incidents: Personal Data Breach Obligations in Poland
Most cyber incidents simultaneously carry the risk of a personal data breach. Ransomware attacks, unauthorized access to systems, cloud environment configuration errors, or customer database leaks can trigger obligations under the GDPR (the General Data Protection Regulation) independently of the reporting duties provided for by NIS2, DORA, or sectoral regulations.
Entrepreneurs should be prepared not only for the technical containment of an incident but also for its correct legal qualification and the fulfillment of obligations towards supervisory authorities. In the event of a personal data breach, a notification to the President of the Personal Data Protection Office (UODO) must be made without undue delay, as a rule, no later than 72 hours after becoming aware of the breach.
These breach notification obligations may be particularly important where the incident involves processing personal data, sensitive personal data, or personal data processed on behalf of another entity. In certain cases, it may also be necessary to notify the data subjects.
An appropriate division of responsibility between data controllers, cloud service providers, and data center operators is also becoming particularly important. In practice, it is precisely contractual relations, incident escalation procedures, and information obligations that determine the ability to effectively manage a crisis and meet statutory notification deadlines.
We advise entrepreneurs on preparing incident response procedures, perform assessments of notification obligations, support organizations during ongoing cyber incidents, and represent clients in proceedings before the President of UODO. We also support the negotiation of contracts with cloud service providers and data center operators, and help integrate GDPR-related obligations with NIS2 and DORA requirements.
DORA Regulation in Poland: Digital Operational Resilience for Financial Entities
The DORA Regulation (EU 2022/2554) introduced uniform rules for digital operational resilience for financial sector entities operating on the European market. The regulation covers approximately 20 categories of financial entities, including banks, payment institutions, investment firms, insurance undertakings, and crypto-asset service providers. In Poland, supervision over compliance with DORA requirements is exercised by the Polish Financial Supervision Authority (KNF).
DORA requires the implementation of a comprehensive ICT risk management framework, the preparation of procedures for the classification and reporting of incidents, and regular testing of the organization’s digital resilience, including – in the case of the largest entities – conducting advanced TLPT-type penetration testing.

The regulation also pays special attention to managing risk associated with ICT and cloud service providers, imposing an obligation to maintain detailed registers of providers and to properly regulate access rights, audit rights, and termination principles in outsourcing contracts.
Another significant change is the direct liability of management bodies for ensuring compliance with DORA. Responsibility for technological risk management cannot be fully transferred to the IT department or external service providers.
We support financial institutions in DORA compliance audits, reviewing and renegotiating contracts with ICT and cloud service providers, building registers of providers, and preparing the organization for inspections conducted by the KNF.
Electronic Communications Law and ICT Compliance in Poland
The new Electronic Communications Law, in force since November 2024, has significantly changed the rules for conducting business in the field of electronic communications and digital marketing. The regulations no longer apply solely to telecommunications entrepreneurs, but also to entities operating in the e-commerce sector, digital service providers, online platform operators, and entrepreneurs using electronic communication as a primary channel for sales and customer service.
In practice, the new provisions require a re-verification of the method for obtaining marketing consents and conducting e-mail, telephone, and SMS campaigns. Sending commercial information and using a telephone or electronic mail for marketing purposes requires the prior, informed, and unambiguous consent of the recipient, which in practice puts an end to the possibility of conducting cold mailing or cold calling activities without a prior relationship with the customer.
In many cases, it is also becoming necessary to verify historically obtained marketing consents for compliance with current standards resulting from the GDPR and the Electronic Communications Law, as well as to remove references to the no longer applicable telecommunications law from forms and clauses.
Another significant area of changes concerns the rules for using cookies, analytical tools, as well as advertising and tracking technologies. User consent must be obtained before storing files used for profiling, analytics, or marketing on the device, with the exception of solutions necessary for the proper functioning of the service, such as maintaining a user session, managing a shopping cart, or executing the login process. Therefore, the correct configuration of cookie banners and consent management mechanisms is becoming increasingly important.
Entrepreneurs operating in e-commerce must also take into account requirements related to the transparency of information provided to customers, the accessibility of digital services for people with disabilities, and the protection of the confidentiality of electronic communications. This applies in particular to the use of instant messengers, chatbots, ticketing systems, and other tools used for customer service that process the content of communication and transmission data of users. In many cases, it will also be necessary to adapt terms of service and purchasing processes to the new information requirements.
Failure to comply with the new obligations may lead to interventions by the President of the Electronic Communications Office (UKE) and the imposition of financial penalties reaching up to 3% of the entrepreneur’s annual revenue.

We provide comprehensive advice on the compliance of e-commerce activities and digital services with the provisions of the Electronic Communications Law, including the verification of marketing processes, consent acquisition mechanisms, cookie policies, terms and conditions, and documentation used in communication with customers.
Cyber Incidents and Criminal Liability in Poland
Cyber incidents increasingly lead not only to disruptions in an enterprise’s operational activities, but also create a necessity to take immediate legal and organizational actions on the part of the attacked organization. In practice, entrepreneurs are more and more frequently facing the takeover of administrative accounts and IT systems, customer data leaks, payment fraud, impersonation of management board members or contractors, and the unauthorized use of online store infrastructure or sales platforms.
Such activities may constitute criminal offenses involving unauthorized access to computer systems or breaching security measures (Article 267 of the Polish Criminal Code), destroying, deleting, or modifying company data and information (Article 268 and 268a of the Polish Criminal Code), disrupting the operation of IT systems and telecommunications infrastructure (Article 269 and Article 269a of the Polish Criminal Code), or computer fraud aimed at achieving financial gain (Article 287 of the Polish Criminal Code).
Criminal liability may also cover the production, acquisition, or sharing of tools, passwords, and data enabling unauthorized access to IT systems (Article 269b of the Polish Criminal Code).

The consequences of such events extend far beyond the IT area and also include legal and financial risks.
An effective response to a cyberattack begins with the proper preservation of electronic evidence and the correct documentation of the course of the incident. Inappropriate actions taken immediately after the detection of an event may hinder the identification of the perpetrators or the effective pursuit of claims. In many cases, entrepreneurs must also fulfil parallel obligations resulting from NIS2, GDPR, or sectoral regulations, including duties related to reporting serious cybersecurity incidents to the competent authorities.
Preventive measures and the proper preparation of the organization before an incident occurs are also gaining increasing importance. The NIS2 Directive and the Act on the National Cybersecurity System require many entrepreneurs to implement a formal security management system, covering risk management, incident response, and business continuity procedures. From the perspective of criminal and regulatory proceedings, the appropriate preparation of the organization often determines the ability to effectively preserve evidence, mitigate the consequences of the incident, and demonstrate that due diligence was exercised by the enterprise and its executives.
We provide legal support during cyber incidents, including the preparation of notifications of suspected criminal offenses, cooperation with law enforcement agencies, and the representation of entrepreneurs in the course of criminal proceedings related to cybercrime. In parallel, we advise on the fulfillment of regulatory obligations arising from NIS2, GDPR, and sectoral regulations, coordinating the actions taken after an incident occurs.
Cybersecurity Compliance and Certification in Poland
The growing number of cybersecurity regulations means that entrepreneurs must not only identify their legal obligations but also demonstrate their actual implementation within the organization.
Increasingly, merely adopting policies and procedures is not enough – supervisory authorities expect the ability to prove the effective operation of security management systems, the appropriate preparation of the organization to respond to incidents, and a regular increase in the level of security.
A key element of the compliance process remains the correct determination of the scope of the entrepreneur’s regulatory obligations. In practice, this requires verifying whether the organization is subject to regulations arising from NIS2 and the Act on the National Cybersecurity System, GDPR, DORA, or other sectoral provisions concerning cybersecurity and digital resilience.
We provide a comprehensive assessment of the enterprise’s regulatory obligations and support in implementing the required procedures and organizational measures, in particular through:
- NIS2 and KSC – analyzing the status of an essential or important entity, support in the self-identification process, registration in the S46 system, and assistance in implementing risk management and incident reporting procedures;
- GDPR and personal data breaches – preparing incident response procedures, assessing notification obligations towards the President of UODO, and integrating data protection requirements into the organization’s cybersecurity system;
- DORA – reviewing the compliance of the ICT risk management framework and adapting documentation and outsourcing contracts to regulatory requirements;
- Cyber Resilience Act – identifying the obligations of manufacturers, importers, and distributors of digital products, preparing documentation, and supporting conformity assessment and certification processes;
- Electronic Communications Law – adapting marketing processes, cookie policies, terms and conditions, and electronic communications to the new regulatory requirements.
An essential element of building organizational resilience remains training and raising employee awareness. We organize training sessions for management personnel and operational teams in the field of cybersecurity and regulatory obligations, supporting entrepreneurs in fulfilling the requirements regarding cyber hygiene and building a security culture, as provided for, among others, by NIS2 and the Act on the National Cybersecurity System.
Legal Support for Cybersecurity Compliance in Poland
We provide comprehensive legal advice in the field of cybersecurity and technological regulations, including the identification of regulatory obligations, implementation of compliance requirements, support in crisis situations, and representation of entrepreneurs before supervisory authorities. We combine experience in the field of new technologies law, personal data protection, sectoral regulations, and corporate criminal law, supporting entrepreneurs in safely conducting business on the Polish and European markets.

FAQ – Cybersecurity law in Poland
What is the main cybersecurity legal framework in Poland?
Poland’s core statutory cybersecurity framework is the Act of 5 July 2018 on the National Cybersecurity System, which entered into force on 28 August 2018. The Act sets out the organisation of the national cybersecurity system, the tasks and obligations of entities within that system, supervision and control mechanisms, and the scope of Poland’s Cybersecurity Strategy.
How does the NIS2 Directive affect cybersecurity obligations in Poland?
The NIS2 Directive broadened cybersecurity obligations across the European Union and required Member States to transpose its rules into national law by 17 October 2024. In Poland, NIS2 was implemented through the Act of 23 January 2026 amending the Act on the National Cybersecurity System and certain other acts, which entered into force on 3 April 2026. The amendments introduced new obligations for key and important entities, subject to applicable transitional rules.
Which institutions coordinate cybersecurity incidents in Poland?
Poland’s cybersecurity architecture includes three national-level CSIRTs: CSIRT NASK, CSIRT GOV and CSIRT MON. These teams coordinate the handling of cybersecurity incidents for assigned entities under the Act on the National Cybersecurity System. CERT Polska operates within NASK, performs CSIRT NASK tasks and has been active since 1996 as Poland’s first incident response team.
What types of cyber threats are most relevant for businesses in Poland?
Businesses in Poland should pay particular attention to phishing and other computer fraud, malware, ransomware, attacks on IT systems, and threats affecting operational technology and industrial control systems. Recent CERT Polska and NASK data show a continued increase in reported cybersecurity incidents, while attacks against the Polish energy sector highlight the importance of OT and ICS security.
Which authority supervises personal data protection in Poland?
Poland’s data protection authority is the President of the Personal Data Protection Office, commonly referred to as UODO. The Polish Personal Data Protection Act was enacted on 10 May 2018 and entered into force on 25 May 2018, the same date from which the GDPR has applied across the European Union.
Can data protection violations lead to criminal sanctions in Poland?
Yes. Under Polish data protection law, certain violations may lead not only to administrative consequences but also to criminal sanctions. Unlawful processing of personal data may be punishable by a fine, restriction of liberty or imprisonment of up to two years, and up to three years where special categories of personal data are involved.
What sanctions may apply under the Polish cybersecurity regime?
Under the amended Act on the National Cybersecurity System, significant financial sanctions may apply to entities that fail to comply with cybersecurity obligations. Depending on the type of entity and infringement, fines may reach up to EUR 10 million or 2% of turnover for essential entities, and up to EUR 7 million or 1.4% of turnover for important entities. For the most serious violations causing a direct and serious cybersecurity threat or a risk of serious material damage or serious disruption of services, fines may reach up to PLN 100 million.